Hacked – advice requested
-
My blog was hacked this weekend. I noticed suspicious activity in the logs. I found a directory called wp-content/uploads/2007/11/images which contained an index.php describing itself as:
/*This file is part of Magic_Toolz for WordPress blogs*/
I haven’t worked out the exact purpose of the hack but it was able to serve up a PHP script which included a hyperlink to a pharmacy site.
So what I’m wondering is:
1. How did the hacker get in? I recently installed wp-cache which requires making wp-content writeable by the web server. Is there a known issue that might exploit this, or should I look elsewhere?
I’ve disabled wp-cache and taken off the write permissions as a precaution.
2. Any suggestions concerning steps I should take after an event like this, to secure the site and prevent further damage?
The web server is running debian etch.
Tim
The topic ‘Hacked – advice requested’ is closed to new replies.